Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 30 May 2001 09:25:48 -0400
From:      Bill Moran <wmoran@iowna.com>
To:        Ryan Masse <mail@max-info.net>
Cc:        FreeBSD-Questions <freebsd-questions@freebsd.org>
Subject:   Re: mysql tcp connection
Message-ID:  <3B14F4DC.322146BE@iowna.com>
References:  <3B144374.996414E9@optonline.net> <3B144ED5.F86EE61B@iowna.com> <3B148021.60CB7680@optonline.net> <00a901c0e8c7$d05a7920$fd00a8c0@Home> <3B14855C.E998927E@iowna.com> <00de01c0e8ca$56b4c820$fd00a8c0@Home>

next in thread | previous in thread | raw e-mail | index | archive | help
Ryan Masse wrote:
> 
> security wise i had removed all anonymous users from the user table.

The "anonymous" users that are included by default have no permissions
on anything. They are there so that someone who logs in anonymously has
no rights to anything. By removing them you may have given anonymous
users indeterminate rights (depending on exactly what you removed) Was
that your intent?

> the '%'
> was for test purposes. A more defined user@'ip/subnet' will be implemented
> once the remote connection has proven itself.

For testing purposes, you should test your security as well.

-Bill

-- 
If a bird in the hand
is worth two in the bush,
then what can I get for
two hands in the bush?

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3B14F4DC.322146BE>